GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            98 advisories
        Filter by severity
        
      
      
    
                    
                      Moodle context freezing
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-3852
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-47407
                      
                      was published
                        for
                        
                          fixpunkt/fp-masterquiz
                        
                        (Composer)
                      Dec 14, 2022 
                    
                  
                    
                      Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-25727
                      
                      was published
                        for
                        
                          phpmyadmin/phpmyadmin
                        
                        (Composer)
                      Feb 13, 2023 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerabilities
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-7341
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle Improper Access Control
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-3733
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows discovery of an author's username
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-3617
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-0218
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site request forgery (CSRF) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-0218
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle External function mod_assign_save_submission does not check due dates
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2159
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle XSS from profile fields from external db
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2152
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to discover hidden course names
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2154
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to obtain sensitive category-detail information
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2158
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to modify "Exclude grade" settings
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2155
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to discover student e-mail addresses
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2151
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle provides calendar-event data without considering whether an activity is hidden
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2156
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to bypass intended access restrictions
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5342
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to read SCORM contents
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5341
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle does not properly implement group-based access restrictions
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5339
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle multiple cross-site scripting (XSS) vulnerabilities
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5336
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site request forgery (CSRF) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5335
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5269
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle mishandles group-based authorization checks
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5268
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle Secure layout contained an insecure link in Boost theme
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-3851
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle Stored HTML in assignment submission comments allowed links to be opened directly
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-3850
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle XSS Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-3847
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API